CVE-2007-2320
papoo < 3.02 - SQL Injection via kontakt.php menuid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2320. PoCs published by Kacper.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in Papoo CMS <= 3.02 via the 'menuid' parameter in kontakt.php. It extracts admin credentials by injecting a UNION-based SQL query to retrieve usernames and password hashes.
Description
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.
Exploits (1)
This exploit targets a SQL injection vulnerability in Papoo CMS <= 3.02 via the 'menuid' parameter in kontakt.php. It extracts admin credentials by injecting a UNION-based SQL query to retrieve usernames and password hashes.